3 ms·
So @indutny sent at least 2.5 million requests, should we start to think more on the practical prevention techniques?
by tszming 13y ago
So @indutny sent at least 2.5 million requests, should we start to think more on the practical prevention techniques?
- pixl97 13y agoA different person achieved retrieving the key in 100,000 requests, which is well within a practical and cheap botnet attack. The next question is how much of the key did they receive in the requests that revealed the key. If it was most or all of the key, a single attack node could query 100,000 different servers with the high probability of retrieving a key at least once with a low probability of being blocked by any of the servers. TL:DR, patch OpenSSL and revoke and rekey all your certs.